Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 088880f584 | |||
| 67d95475ee | |||
| aec04bfe02 | |||
| a54c42271c |
@@ -278,11 +278,11 @@ func runServer() {
|
|||||||
// is the follow-up (M5 partial).
|
// is the follow-up (M5 partial).
|
||||||
w.Header().Set("Content-Security-Policy",
|
w.Header().Set("Content-Security-Policy",
|
||||||
"default-src 'self'; "+
|
"default-src 'self'; "+
|
||||||
"script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; "+
|
"script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net; "+
|
||||||
"style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; "+
|
"style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; "+
|
||||||
"img-src 'self' data: https:; "+
|
"img-src 'self' data: https:; "+
|
||||||
"connect-src 'self'; "+
|
"connect-src 'self'; "+
|
||||||
"font-src 'self' data: https://cdn.jsdelivr.net")
|
"font-src 'self' data: https://cdn.jsdelivr.net https://fonts.scalar.com")
|
||||||
w.Header().Set("Content-Type", "text/html")
|
w.Header().Set("Content-Type", "text/html")
|
||||||
w.Write([]byte(`<!doctype html><html><head><title>API</title>
|
w.Write([]byte(`<!doctype html><html><head><title>API</title>
|
||||||
<meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
|
<meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
|
||||||
|
|||||||
@@ -0,0 +1,72 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestReleaseAPIURL pins the contract that downstream code (the updater and
|
||||||
|
// /install.sh) relies on: only https://host/owner/repo produces an API URL,
|
||||||
|
// everything else errors. Plain HTTP must be rejected — M7 makes auto-update
|
||||||
|
// only trust TLS-protected release feeds, since the binary it downloads is
|
||||||
|
// exec'd as root.
|
||||||
|
func TestReleaseAPIURL(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
in string
|
||||||
|
want string
|
||||||
|
wantErr string // substring expected in the error message; "" means success
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "valid https repo",
|
||||||
|
in: "https://tea.example.com/owner/repo",
|
||||||
|
want: "https://tea.example.com/api/v1/repos/owner/repo/releases/latest",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "http rejected",
|
||||||
|
in: "http://tea.example.com/owner/repo",
|
||||||
|
wantErr: "https",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "ssh scheme rejected",
|
||||||
|
in: "ssh://tea.example.com/owner/repo",
|
||||||
|
wantErr: "https",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "missing repo segment",
|
||||||
|
in: "https://tea.example.com/owner",
|
||||||
|
wantErr: "owner/repo",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "extra path segments",
|
||||||
|
in: "https://tea.example.com/owner/repo/extra",
|
||||||
|
wantErr: "owner/repo",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "empty",
|
||||||
|
in: "",
|
||||||
|
wantErr: "https",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
got, err := releaseAPIURL(tt.in)
|
||||||
|
if tt.wantErr == "" {
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("unexpected error: %v", err)
|
||||||
|
}
|
||||||
|
if got != tt.want {
|
||||||
|
t.Errorf("got %q, want %q", got, tt.want)
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if err == nil {
|
||||||
|
t.Fatalf("expected error containing %q, got nil (result %q)", tt.wantErr, got)
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), tt.wantErr) {
|
||||||
|
t.Errorf("error %q does not contain %q", err.Error(), tt.wantErr)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -65,6 +65,10 @@ type RemoveInput struct {
|
|||||||
Name string `path:"name" example:"htop" doc:"Package to remove"`
|
Name string `path:"name" example:"htop" doc:"Package to remove"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type UpgradeOneInput struct {
|
||||||
|
Name string `path:"name" example:"htop" doc:"Package to upgrade"`
|
||||||
|
}
|
||||||
|
|
||||||
// SSE event types for streaming package operations.
|
// SSE event types for streaming package operations.
|
||||||
type PkgOutputEvent struct {
|
type PkgOutputEvent struct {
|
||||||
Line string `json:"line" doc:"One line of the package manager's terminal output"`
|
Line string `json:"line" doc:"One line of the package manager's terminal output"`
|
||||||
@@ -162,6 +166,25 @@ func registerPackages(api huma.API, pm manager) {
|
|||||||
bin, args := pm.upgradeArgs()
|
bin, args := pm.upgradeArgs()
|
||||||
streamOp(ctx, send, bin, args)
|
streamOp(ctx, send, bin, args)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
sse.Register(api, huma.Operation{
|
||||||
|
OperationID: "packages-upgrade-one",
|
||||||
|
Method: "POST",
|
||||||
|
Path: "/api/packages/upgrade/{name}",
|
||||||
|
Summary: "Upgrade a single package (streamed)",
|
||||||
|
Description: "Upgrades the named package to its latest version, streaming the " +
|
||||||
|
"package manager's output live. apt uses `install --only-upgrade` so the " +
|
||||||
|
"package must already be installed; dnf/pacman handle this natively.",
|
||||||
|
Tags: []string{tagPackages},
|
||||||
|
Metadata: op("write"),
|
||||||
|
}, pkgEvents, func(ctx context.Context, in *UpgradeOneInput, send sse.Sender) {
|
||||||
|
if validateName(in.Name) != nil {
|
||||||
|
send.Data(PkgErrorEvent{Message: "invalid package name: " + in.Name})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
bin, args := pm.upgradeOneArgs(in.Name)
|
||||||
|
streamOp(ctx, send, bin, args)
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// streamOp runs a package write and streams its combined output to the client.
|
// streamOp runs a package write and streams its combined output to the client.
|
||||||
@@ -260,11 +283,11 @@ func result(pm manager, pkgs []Package) *ListOutput {
|
|||||||
func (m manager) installArgs(name string) (string, []string) {
|
func (m manager) installArgs(name string) (string, []string) {
|
||||||
switch m.name {
|
switch m.name {
|
||||||
case "dnf":
|
case "dnf":
|
||||||
return "dnf", []string{"install", "-y", "--", name}
|
return "dnf", []string{"install", "-y", name}
|
||||||
case "apt":
|
case "apt":
|
||||||
return "apt-get", []string{"install", "-y", "--", name}
|
return "apt-get", []string{"install", "-y", name}
|
||||||
case "pacman":
|
case "pacman":
|
||||||
return "pacman", []string{"-S", "--noconfirm", "--", name}
|
return "pacman", []string{"-S", "--noconfirm", name}
|
||||||
}
|
}
|
||||||
return "", nil
|
return "", nil
|
||||||
}
|
}
|
||||||
@@ -272,11 +295,11 @@ func (m manager) installArgs(name string) (string, []string) {
|
|||||||
func (m manager) removeArgs(name string) (string, []string) {
|
func (m manager) removeArgs(name string) (string, []string) {
|
||||||
switch m.name {
|
switch m.name {
|
||||||
case "dnf":
|
case "dnf":
|
||||||
return "dnf", []string{"remove", "-y", "--", name}
|
return "dnf", []string{"remove", "-y", name}
|
||||||
case "apt":
|
case "apt":
|
||||||
return "apt-get", []string{"remove", "-y", "--", name}
|
return "apt-get", []string{"remove", "-y", name}
|
||||||
case "pacman":
|
case "pacman":
|
||||||
return "pacman", []string{"-R", "--noconfirm", "--", name}
|
return "pacman", []string{"-R", "--noconfirm", name}
|
||||||
}
|
}
|
||||||
return "", nil
|
return "", nil
|
||||||
}
|
}
|
||||||
@@ -293,6 +316,21 @@ func (m manager) upgradeArgs() (string, []string) {
|
|||||||
return "", nil
|
return "", nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// upgradeOneArgs upgrades a single package to its latest version. apt's
|
||||||
|
// `install --only-upgrade` is the safe variant (won't install if absent);
|
||||||
|
// pacman -S re-syncs to latest; dnf upgrade is naturally scoped by name.
|
||||||
|
func (m manager) upgradeOneArgs(name string) (string, []string) {
|
||||||
|
switch m.name {
|
||||||
|
case "dnf":
|
||||||
|
return "dnf", []string{"upgrade", "-y", name}
|
||||||
|
case "apt":
|
||||||
|
return "apt-get", []string{"install", "--only-upgrade", "-y", name}
|
||||||
|
case "pacman":
|
||||||
|
return "pacman", []string{"-S", "--noconfirm", name}
|
||||||
|
}
|
||||||
|
return "", nil
|
||||||
|
}
|
||||||
|
|
||||||
// --- parsers (pure, tested) --------------------------------------------------
|
// --- parsers (pure, tested) --------------------------------------------------
|
||||||
|
|
||||||
// parseTabbed reads "name\tversion" lines (dpkg-query / rpm output).
|
// parseTabbed reads "name\tversion" lines (dpkg-query / rpm output).
|
||||||
|
|||||||
@@ -499,9 +499,12 @@ func diskInfo() []DiskInfo {
|
|||||||
disks := []DiskInfo{}
|
disks := []DiskInfo{}
|
||||||
seen := map[string]bool{}
|
seen := map[string]bool{}
|
||||||
for _, e := range entries {
|
for _, e := range entries {
|
||||||
// Only real block devices; skip pseudo filesystems and snap's squashfs
|
// ponytail: filter by fstype, not device path. LXC/Docker containers
|
||||||
// loop mounts that would otherwise clutter the list.
|
// expose their rootfs as a ZFS dataset name, an overlayfs, or a bind
|
||||||
if !strings.HasPrefix(e.Device, "/dev/") || e.FSType == "squashfs" || seen[e.Mountpoint] {
|
// path — never /dev/* — so a "must start with /dev/" check silently
|
||||||
|
// returned no disks on those hosts. statfs + non-zero blocks already
|
||||||
|
// excludes mounts that aren't real storage.
|
||||||
|
if pseudoFS[e.FSType] || seen[e.Mountpoint] {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
var st syscall.Statfs_t
|
var st syscall.Statfs_t
|
||||||
@@ -522,6 +525,39 @@ func diskInfo() []DiskInfo {
|
|||||||
return disks
|
return disks
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// pseudoFS lists kernel-virtual filesystems that show up in /proc/mounts but
|
||||||
|
// aren't user-facing storage. squashfs covers snap loop mounts; fuse.lxcfs is
|
||||||
|
// LXC's per-container /proc/* shim. Anything not on this list and statfs-able
|
||||||
|
// with non-zero blocks is treated as real storage — covers ext*, btrfs, xfs,
|
||||||
|
// zfs, nfs, cifs, overlay, and the bind-mount cases inside Proxmox LXC.
|
||||||
|
var pseudoFS = map[string]bool{
|
||||||
|
"autofs": true,
|
||||||
|
"binfmt_misc": true,
|
||||||
|
"bpf": true,
|
||||||
|
"cgroup": true,
|
||||||
|
"cgroup2": true,
|
||||||
|
"configfs": true,
|
||||||
|
"debugfs": true,
|
||||||
|
"devpts": true,
|
||||||
|
"devtmpfs": true,
|
||||||
|
"fuse.gvfsd-fuse": true,
|
||||||
|
"fuse.lxcfs": true,
|
||||||
|
"fusectl": true,
|
||||||
|
"hugetlbfs": true,
|
||||||
|
"mqueue": true,
|
||||||
|
"nsfs": true,
|
||||||
|
"overlay": true,
|
||||||
|
"proc": true,
|
||||||
|
"pstore": true,
|
||||||
|
"ramfs": true,
|
||||||
|
"rpc_pipefs": true,
|
||||||
|
"securityfs": true,
|
||||||
|
"squashfs": true,
|
||||||
|
"sysfs": true,
|
||||||
|
"tmpfs": true,
|
||||||
|
"tracefs": true,
|
||||||
|
}
|
||||||
|
|
||||||
func netInfo() []NetInterface {
|
func netInfo() []NetInterface {
|
||||||
ifaces, err := net.Interfaces()
|
ifaces, err := net.Interfaces()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
Reference in New Issue
Block a user